First published: Sat Feb 22 2014(Updated: )
The server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote authenticated users to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Business Intelligence | =8.4.1 | |
IBM Cognos Business Intelligence | =10.1 | |
IBM Cognos Business Intelligence | =10.1.1 | |
IBM Cognos Business Intelligence | =10.2 | |
IBM Cognos Business Intelligence | =10.2.1 | |
IBM Cognos Business Intelligence | =10.2.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0854 has a medium severity rating due to its potential to allow unauthorized file access by authenticated users.
To fix CVE-2014-0854, upgrade IBM Cognos Business Intelligence to a version that includes the relevant security updates.
CVE-2014-0854 affects IBM Cognos Business Intelligence versions 8.4.1, 10.1, 10.1.1, 10.2, 10.2.1, and 10.2.1.1 before specific fix packs.
CVE-2014-0854 allows for XML External Entity (XXE) attacks which can lead to arbitrary file reading.
CVE-2014-0854 is exploitable remotely by authenticated users who can craft specific XML documents.